What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,957 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 8h ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 19h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
Should cyber insurance be part of your business backup plan?
Insurance is all about managing risk. Unlike policies that are legally required for driving a car or taking out a mortgage, cyber insurance is optional. But for small businesses in particular, is cyber cover worth getting? If they…
-
The serpent’s tongue: Luring the Python out of its den
This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Pytho…
-
Sony Nerfs Videogame Ownership
Legal intern Suzanne Castillo co-authored of this post. Playstation’s decision to kill physical game discs is the latest attack on our diminishing rights to access and engage with culture digitally. Rent-seeking corporations and n…
-
A Bridge Not Too Far!
On our Irkutsk–Yakutsk–Magadan–Yakutsk winter road-trip we finally rolled into civilization and were fast approaching Yakutsk Airport, from where we d soon have the good fortune to be heading home. But before the triumphant finale…
-
Threat Actors Achieve Persistence After SQL Injection
See how a threat actor used SQL injection and BadIIS to gain persistence, disable Windows Defender, and quietly install a cryptominer.
-
Minimizing Machine Work Maximizes Human Work
Minimizing machine work maximizes human work header/images/minimizing-machine-work-maximizes-human-work.webp/images/minimizing-machine-work-maximizes-human-work.webp Behavioral geneticists like Robert Plominhttps://en.wikipedia.or…
-
The Good, the Bad and the Ugly in Cybersecurity – Week 28
Authorities launch Operation First Light 2026, attackers deploy Forg365 to hijack Microsoft accounts, and rival cyberspies breach Pakistani police networks.
-
Building Our Future Together
In my first weeks as Executive Director of EFF, I’ve been reminded every day how consequential this moment is in determining what kind of future we will have. We are on the edge. What each one of us steps up to do – with our exper…
-
Automated Moderation Is Here to Stay—Accountability Must Keep Pace
This post is part 2 in a series about automated content moderation. Read the first post here . When whistleblower Frances Haugen leaked a set of documents from Meta in 2020, among the revelations was a jarring statistic: The compa…
-
Guide to System Hardening: Checklist & Best Practices [2026] | Huntress
Threat actors want an easy way in. Use this practical system-hardening checklist to close gaps and learn how to secure your environment today.
-
"We Want Texans to Know Their Rights": Q&A with Mayday Health on the Impact of Surveillance on Abortion Care
Last May, EFF reported that a sheriff’s office in Texas searched data from more than 83,000 automated license plate reader (ALPR) cameras to track down a woman suspected of self-managing an abortion. ALPRs are promoted as tools fo…
-
The House Passed The KIDS Act—The Senate Should Reject It
Last week, the House voted on the KIDS Act , a disjointed package of legislation that seeks to control Americans’ web browsing and private messaging. The package combines a revised version of the Kids Online Safety Act ( KOSA), wi…
-
Patch for Windows Defender 0-day could allow attackers to fill hard disk
The feud between NightmareEclipse and Microsoft shows no signs of resolving soon.
-
Reduce Human Risk | Build a Strong Security Awareness Training Program | Huntress
Build a security awareness training program that actually changes user behavior. Huntress Managed SAT delivers engaging content, phishing sims, and results.
-
European Commission Chooses to Keep EU Users Locked Up Behind Big Tech’s Gates
Users are always seeking more control over their social networking experience to make it better, whether to improve privacy or enhance flexibility. Interoperability between social networking platforms like Facebook and TikTok has …
-
I Wrote a New Book for Corelight
TLDR: I wrote a new book for Corelight called NDR Essentials . It's free at that link. This is the 10th book that I've authored or co-authored. The rest are all posted at taosecurity.com . Why? It was time . That’s what I thought …
-
Conditional Access Misconfigurations Exposed 55 Orgs with MFA On
Two Microsoft 365 attacks got through Conditional Access policies that seemed fully configured. Learn what went wrong and how Huntress Managed ISPM catches these gaps first.
-
Weekly Update 511: Live from my Riad in Marrakech
How s this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow Anyway, about those data breaches... This week I m talking about the futility of attempting to remove piss from a pool , ye…
-
LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress
LoTL abuse hides in plain sign, using legit tools like PowerShell and RMM software. Learn how to spot the warning signs that separate from routine IT work.
-
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination. The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File In…
-
Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud
Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims. Read more in my article on the Hot for Security blog.
-
Meta Phishers Abuse Business Account Manager Service | Huntress
Huntress is tracking a threat actor group as they evolve a phishing attack that uses a Facebook feature to send the initial spam lure.
-
Getting to know: Gemma Ungoed-Thomas
Gemma Ungoed-Thomas has spent over two decades performing what she considers the best and most exciting roles in Government and for the very first time, she s ready to talk about it in this exclusive interview with Assured s Elean…
-
5 Cybersecurity Lessons From Taylor & Travis’s Wedding
“Long Live” strong security! Taylor Swift & Travis Kelce’s wedding offers real cybersecurity lessons on layered defense, MFA, deception tools, and more.
-
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus…
-
Plain Text Passwords: The Risks of Storing Them
Plain text passwords are a critical security risk. See a real attack where exposed credentials led to a breach and how Huntress helps prevent it.
-
"Having Birth": What Florida's New Security Law Is Actually For
Building a family in Florida now depends on where you were born. The Governor says that's the point. There's also prison time.
-
On the shortest of Bogotá stays – the curious case of the coffee-bean ashtrays.
It was a short flight from Lima, Peru up to Bogotá – the capital of Colombia. We had just one day here, and it was a strictly business one at that – alas, no tourism this time. No shots of unusual nature or off-the-beaten-path spo…
-
Swimming Pools, Pee, and Trying to Delete Your Data From the Internet
I can t recall if someone else originally came up with this saying or if I said it in some off-the-cuff comment and it just propagated, but since it s often attributed back to me , I ll relay it here regardless: Trying to delete y…
-
FBI Seizes NetNut Proxy Platform, Popa Botnet
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alaru…
-
Guide to Cloud Application Security: Must-Knows and No-No’s | Huntress
Cloud application security keeps threat actors away from your data. We share practical ways to protect your apps and why it matters for your team today.
-
LGBT Q&A: How Can I Wipe Online Data That Points To My Queer Identity?
This Pride, we’re answering all your digital rights questions in season two of our initiative, LGBT Q A . You Asked: Is there a way for me to wipe data about me online that could point to my queer identity? EFF’s Answer: You canno…
-
Partners – nice to see you; here in sunny Peru!
Hola folks! Lima oceanside walkies – done; next up – our LatAm partner conference, with 220 guests, from 19 countries. So. What? Why?! It all rather straightforward really. Practically any mass-market product is sold not directly …
-
Celebrating Canada Day with Localized Managed Phishing
Huntress Managed SAT now offers localized phishing simulations for Canada, using familiar, country-specific brands and scenarios to provide more effective security awareness training for your learners.
-
Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?
Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hair…
-
Lateral Movement Attack: Techniques, Detection & Prevention
Huntress explains lateral movement attacks, how attackers move through networks, common techniques like pass-the-hash, and how Managed EDR stops lateral movement.
-
In the Peruvian capital – an urban coastal ramble.
Cities come in all shapes and sizes. There are the standout urban projects – like the island-city-state of Singapore. There are megacities that really lucked out with phenomenal natural beauty all around them – Rio de Janeiro, for…
-
Security Roundup June 2026
Curated advice, guidance, learning and trends in cybersecurity and privacy, as chosen by our consultants. New initiative to foster female cybersecurity leadership comes to Ireland A new initiative aiming to encourage people from d…
-
WhatsApp to begin rolling out usernames
Curated by Sherpa Intelligence : Your Guide Up a Mountain of Information WhatsApp to begin rolling out usernames Summary: WhatsApp users may begin to register a “claim” for their preferred username. Can only be done via app, will …
-
Four days to Yakutsk Airport.
Leaving Zyryanka, it struck me: the nearest airport with regular flights to the capital of our vast and boundless homeland is a full four days away by car! Well, if you really push it and don t sleep at night, you could manage it …
-
Scammers race to cash in on Venezuelan earthquake disaster
Scammers wasted no time exploiting Venezuela's devastating earthquake, with researchers uncovering 212 newly-registered relief-themed domains in just five days. Read more in my article on the Hot for Security blog.
-
No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack
Huntress is seeing an ongoing password spray attack against Microsoft Azure CLI that originates from an IPv6 address range controlled by LSHIY LLC.
-
Anton’s Security Blog Quarterly Q2 2026
My Anton’s Security Blog Quarterly covers both Anton on Security and my posts from Google Cloud blog , Google Cloud community blog , and our Cloud Security Podcast ( subscribe on Spotify, now with VIDEO ). Top 10 posts with the mo…
-
Weekly Update 510: Live From Mallorca with Scott Helme
How s the view?! Back to business, it s now 8 years ago that Scott and I thought it would be a cool idea to build Why no HTTPS? We used the site to shame companies for not implementing their transport later security property, and …
-
Microsoft 365 Hardening and Huntress Managed ISPM
Most Microsoft 365 environments are missing more than half of the recommended security controls, even with tooling in place. Here's why that happens and what Huntress Managed ISPM does about it.
-
LGBT Q&A: What Data Are Companies in the UK Collecting When Verifying My Age?
This Pride, we’re answering all your digital rights questions in season two of our initiative, LGBT Q A . You Asked: I live in the UK, and we have age verification now on a bunch of websites (including Reddit) and now on iPhones. …
-
EFF to Gov. Pritzker: Veto Illinois’ HB 5511
The Illinois legislature recently passed House Bill 5511 , which imposes a sweeping, device-level age-gating framework across nearly all internet-enabled hardware, operating systems, and online services. This well-intentioned but …
-
Victory! Supreme Court Says Constitution Protects People’s Location Data
You have an expectation of privacy in location data that reveals your movements in the physical world, and even short-term surveillance of these movements is a search subject to the Fourth Amendment, the U.S. Supreme Court ruled t…
-
29th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Polymarket, a large cryptocurrency-based prediction market, has confirmed a supply …
-
These Recent Insider Threat Allegations
Last fetch 17m ago · 1 new · 2 source error(s)